
mora-hwbp
Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

Self-referenced local contrast for knowledge-poison detection in retrieval-augmented generation

A curated collection of resources for learning and researching LLM prompt injection attacks, defenses, and security.

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

CVE-2026-20685 - Draft or TODO

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

A tool to find folders excluded from AV real-time scanning using a time oracle

Lifetime AMSI bypass

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Detect EDR's exceptions by inspecting processes' loaded modules

Attempt at Obfuscated version of SharpCollection

Leak NTLM via Website tab in teams via MS Office

Weaponizing DCOM for NTLM Authentication Coercions